VYPR
Critical severity9.4NVD Advisory· Published Mar 10, 2026· Updated May 7, 2026

CVE-2025-69614

CVE-2025-69614

Description

Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2025-10-27, fixed 2025-10-31.

Affected products

2
  • cpe:2.3:a:telekom:account_management_portal:*:*:*:*:*:*:*:*
    Range: <2025-10-27
  • Deutsche Telekom AG/Telekom Account Management Portaldescription

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.